Menu

Category Archives: All

Everything

Sophisticated iPhone hacking went unnoticed for over two years
News Wrap: Dentist Offices Hit By Ransomware, Venmo Faces Privacy Firestorm
When you think how infamous NHS-pwning malware’s still hitting the unwary, it’ll make you WannaCry – Kaspersky
Botnet targets set-top boxes using Android OS

Reading Time: ~ 2 min. Cybercriminals use Botnets to Launch Attacks on Social Media According to a new report, more than half of all login attempts on social media sites are fraudulent, and at least 1 in 4 new account creation attempts are also fraudulent. With the sheer number of potential victims these types of […]

Hardening Gluster Installations with TLS
Hear me speak at “Conversations from the Vault” in London
Apple apologizes for humans listening to Siri clips, changes policy

* CVE-2019-11500: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes

Rebuilt with newer nghttp2 —- This update includes the latest upstream release of `mod_http2`, version **1.15.3**. Upstream changes include: * fixes Timeout vs. KeepAliveTimeout behaviour, see PR 63534. * Fixes stream cleanup when connection throttling is in place. * Counts stream resets by client on streams initiated by client as cause for connection throttling. * […]

Despite billions in spending, your ‘military grade’ network will still be leaking data
Google warns of system-controlling Chrome bug
The top reason businesses make a cyber insurance claim – Business Email Compromise

An update that fixes one vulnerability is now available.

I just love your accent – please, have a new password
Google takes a little more responsibility for its Android world, will cough up bounties for mega-popular app bugs
TGI Fridays Delivers Customer Indigestion Over Data Exposure

New version 3.0.3, Security fix for CVE-2019-13619

Update to 2.6.7

FIN6 Switches Up PoS Tactics to Target E-Commerce

security update

An update that solves four vulnerabilities and has three fixes is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Capital One ‘hacker’ hit with fresh charges: She burgled 30 other AWS-hosted orgs, Feds claim

Several security issues were fixed in Apache.

Hongxu Chen found several issues in djvulibre, a library and set of tools to handle images in the DjVu format.

New version 3.0.3, Security fix for CVE-2019-13619

Update to 2.6.7

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Google Targets Data-Abusing Apps with Bug Bounty Launch
Which Linux Distros Are Most Focused On Privacy?
Venmo’s Public Transactions Policy Stirs Privacy Concerns
Ex-Amazon worker – suspected of hacking Capital One – faces charges of breaching 30 other companies to mine cryptocurrency
Web clickjacking fraud makes a comeback thanks to JavaScript tricks

The package libnghttp2 before version 1.39.2-1 is vulnerable to denial of service.

The package go-pie before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package go before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.

The package gettext before version 0.20.1-1 is vulnerable to arbitrary code execution.

Critical Cisco VM Bug Allows Remote Takeover of Routers
Innovation on the Dark Web: How Bad Actors Are Keeping Pace
Video captures glitching Mississippi voting machines flipping votes
Microsoft may still be violating privacy rules, says Dutch regulator
Smashing Security #143: Hacking from outer space, Ukrainian cryptomining, and deepfaked Canadians

An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

Ceph could be made to crash if it received specially crafted network traffic.

Today’s Resident Evil: Ransomware crooks think local, not global, prey on schools, towns, libraries, courts, cities…
Ways to Help Keep Your Business Systems Secure
Elderly China Chopper Tool Still Going Strong in Multiple Campaigns
Are US border cops secretly secreting GPS trackers on vehicles without a warrant? EFF lawyers want to know

Ghostscript could be made to access arbitrary files if it opened a specially crafted file.

Two security vulnerabilities were found in the Apache HTTP server. CVE-2019-10092

Come on, hackers, do your worst ‒ Facebook opens Portal gizmo to Pwn2Own exploit fest
TrickBot Targets Verizon, T-Mobile, Sprint Users to Siphon PINs

USN-4110-1 introduced a regression in Dovecot.

Popular CamScanner app for Android infected with nasty malware
Apple Updates Privacy Policies After Siri Audio Recording Backlash
Google Squashes High-Severity Blink Browser Engine Flaw
Emergency iOS patch fixes jailbreaking flaw for second time
Defense Takeaways from Three Adversary Playbooks
Dangerous Cryptomining Worm Racks Up 850K Infections, Self-Destructs
Magecart Hits 80 Major eCommerce Sites in Card-Skimming Bonanza

An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

An update that fixes 9 vulnerabilities is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

NASA astronaut accused of accessing ex-wife’s bank account from space

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Time to spin the wheel of pwnage! This week, malware can infect your…. Android set-top box!

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Romance scams – 80 people charged with ripping off millions of dollars
Android 10 coming soon, with important privacy upgrades
Report: 53% of social media logins are fraudulent
Dixons hits back at McAfee’s £30m antivirus sueball: Your AV didn’t work on Windows 10S
Android PDF app with just 100m downloads caught sneaking malware into mobes

security update

Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT

An update that solves 7 vulnerabilities and has three fixes is now available.

Several vulnerabilities have been found in the Apache HTTPD server. CVE-2019-9517

ghostscript: -dSAFER escape via .buildfont1 (701394) (CVE-2019-10216) SL7 x86_64 ghostscript-9.25-2.el7_7.1.i686.rpm ghostscript-9.25-2.el7_7.1.x86_64.rpm ghostscript-cups-9.25-2.el7_7.1.x86_64.rpm ghostscript-debuginfo-9.25-2.el7_7.1.i686.rpm ghostscript-debuginfo-9.25-2.el7_7.1.x86_64.rpm libgs-9.25-2.el7_7.1.i686.rpm libgs-9.25-2.el7_7.1.x86_64.rpm ghostsc [More…]

zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) SL7 x86_64 zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62- [More…]

opensc: Buffer overflows handling responses from Muscle Cards in card- muscle.c:muscle_list_files() (CVE-2018-16391) * opensc: Buffer overflows handling responses from TCOS Cards in card- tcos.c:tcos_select_file() (CVE-2018-16392) * opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len() (CVE-2018-16393) * opensc: Buffer overflow h [More…]

gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More…]

Malicious App on Google Play Tallies 100 Million Downloads
Imperva Firewall Breach Exposes Customer API Keys, SSL Certificates
We will hack back if you tamper with our shiz, NATO declares to world’s black hats
Why is learning Python important in Data Science?
Oil and Gas Firms Targeted By New LYCEUM Threat Group

Security fix for CVE-2019-13509

An update that fixes three vulnerabilities is now available.

GitHub joins WebAuthn club
Hostinger upgrades password security after 14m accounts breached